Opportunity Hub

Real-time Pulse

Turn on alerts

Your Match Alerts

Discovery alerts are based on your last 3 job and event pulses.

Vercel

Senior Product Security Engineer

Vercel

Remote
Full-Time

Posted 8 hours ago • Via weworkremotely.com

Description

Job Overview

  • Role: Senior Product Security Engineer
  • Company: Vercel
  • Location: Remote
  • Employment Type: Full-Time
  • Category / Department: Full-Stack Programming
  • Salary: Competitive / Not Disclosed — confirm during interview
  • Listing Source: WeWorkRemotely

Job Description

Headquarters: Remote - United States

About Vercel:


Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web.


Our mission is to enable the world to ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things.

About the Role:


We are looking for a Senior Product Security Engineer to join our security team to drive critical product security initiatives across Vercel’s products and platform. Your core focus will be on threat modeling, open-source software security, secure code review, SDLC tooling, and bug bounty program management. You will support both our internal product engineering teams and customer-facing security programs, ensuring that security is embedded throughout our development lifecycle and that our platform earns the trust of developers and end-users alike.


As a senior member of the team, you will lead cross-organizational security projects and champion a security-first culture within Vercel’s engineering organization. This is a high-impact role with broad scope – your work will not only secure Vercel’s core infrastructure and products (built with Next.js, Node.js, and serverless architecture), but also influence the security of the open-source ecosystems we contribute to.


If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you're located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team.


What You Will Do:



  • Threat Modeling & Design Review: Partner with engineering and product teams to perform threat modeling for new and existing features. Identify potential risks early in the design phase and recommend security controls or design changes to mitigate threats. You will ensure security concerns are addressed from the inception of features through deployment.

  • Secure Code Review: Conduct secure code reviews and security assessments on products and services built with Next.js, Node.js, and our serverless backend. You’ll uncover code-level vulnerabilities, provide actionable remediation guidance to developers, and establish best practices for secure coding across the engineering team.

  • Open Source Security Management: Oversee Vercel’s open-source security efforts. This includes monitoring and coordinating fixes for vulnerabilities in third-party open-source packages we use (as a consumer) and ensuring the security of the open-source projects we maintain and publish (as a contributor/publisher, e.g. Next.js). You will work with maintainers and the community on responsible disclosure and patching of security issues in open-source code.

  • SDLC Tooling & Automation: Evaluate, select, and integrate security tools into our Software Development Life Cycle. You will drive the implementation of automated security checks – for example, using GitHub Advanced Security (GHAS) and other static analysis, dependency scanning, and secret detection tools – directly in our CI/CD pipelines and GitHub workflows. By embedding security tooling into developer workflows, you will help catch issues early and reduce manual effort.

  • Bug Bounty Program Management: Own and expand Vercel’s bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues are promptly addressed, and coordinate cross-team efforts to remediate and learn from reported vulnerabilities. You’ll also work on making our bug bounty a world-class, researcher-friendly program, including refining policies, scope, and engagement to encourage high-quality submissions.

  • Cross-Organizational Security Initiatives: Lead and contribute to security projects that span multiple teams and disciplines. For example, you might drive a company-wide upgrade to a more secure framework, implement a new authentication/authorization mechanism in collaboration with product teams, or roll out a security awareness program for engineers. You will act as a security champion across the org, aligning stakeholders from Engineering, DevOps, Product, and other groups to implement lasting security improvements.

  • Customer-Facing Security Support: Work closely with customer success and product marketing on security-related initiatives that impact our users. This may involve contributing to security documentation and whitepapers, assisting with customer security questionnaires or audits by providing product security expertise, and communicating our security features and best practices to build customer trust in the platform.


About You:



  • Experienced Security Engineer: You have 5+ years of experience in an Product Security or Product Security role (or related field), with a track record of securing web products and services. You’re well-versed in the fundamentals of product security and have hands-on experience finding and fixing vulnerabilities.

  • Web Tech Stack Proficiency: Strong familiarity with JavaScript/TypeScript and Node.js runtime security. Experience with modern web frameworks (ideally Next.js or React and Node-based frameworks) and understanding of their security considerations. You can read and review code in these technologies to spot security flaws.

  • Threat Modeling & SDLC Expertise: Demonstrated ability to perform threat modeling and architectural risk analysis for complex product. You understand how to integrate security into a fast-paced SDLC without slowing it down. Experience implementing or working with secure development lifecycle practices (secure design, code review, pentesting, etc.) is required.

  • Security Tools & Automation: Hands-on experience with product security tooling such as static product security testing (SAST), dynamic testing (DAST), dependency vulnerability scanners, and CI/CD pipeline security integration. Familiarity with GitHub Advanced Security or similar tools for code scanning and secret detection is a strong plus.

  • Open Source and Supply Chain Security: Knowledge of open-source security best practices. You have experience dealing with open-source dependencies and package management security (e.g., handling vulnerability advisories, using tools like Dependabot or Snyk). Bonus if you have contributed to or maintained open-source projects, especially security-related ones.

  • Bug Bounty & Vulnerability Management: Exposure to running or participating in a bug bounty program or vulnerability disclosure process. You know how to assess externally reported issues, reproduce and validate vulnerabilities, and coordinate fixes. You stay up-to-date on the latest vulnerabilities (OWASP Top 10, emerging threats) and methods to mitigate them.

  • Cloud & Serverless Security Understanding: Solid understanding of cloud architecture and serverless environments from a security perspective. You are familiar with securing products on cloud platforms (e.g., securing serverless functions, protecting APIs, managing secrets and keys). Experience with related cloud security concepts or tools is a plus.

  • Technical Leadership: Proven ability to drive security initiatives and influence engineering teams to adopt best practices. You can work cross-functionally to achieve security goals – for example, rolling out a new security tool or standard across many engineers. (While we emphasize technical skills, this senior role requires you to effectively communicate and lead within the organization to get things done.)


Bonus If You:



  • Have prior software development experience beyond security (e.g. as a frontend or backend engineer). Being able to empathize with developers and write or contribute code will help you integrate security seamlessly into development.

  • Hold relevant security certifications or recognitions (for example, OSCP, OSWE, CISSP, or notable bug bounty hall of fame entries). These demonstrate your depth of knowledge, though they are not required.

  • Experience with security policy-as-code or infrastructure as code security (for instance, using tools like Open Policy Agent, Terraform security checks, etc.). This shows you can bring security into the automation and infrastructure realm.

  • Have built or implemented security features in a product (such as authentication systems, encryption, secure CI/CD pipelines) or contributed to security community projects/tools.

  • Are an active participant in the security community (e.g., contributing to open source security projects, writing blog posts or research, attending or speaking at security conferences). A passion for continuous learning and sharing knowledge is always a plus on our team.


 


Benefits:



  • Competitive compensation package, including equity.

  • Inclusive Healthcare Package.

  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.

  • Flexible Time Off.

  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.


The San Francisco, CA base pay range for this role is $196,000.00 - $294,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process. 


Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.


 


To apply: https://weworkremotely.com/remote-jobs/vercel-senior-product-security-engineer

Salary & Compensation

The salary for this role is not publicly disclosed. Based on industry benchmarks, roles of this type in India or remote-first companies typically offer compensation in line with market rates for the experience level required. We recommend researching platforms like Glassdoor, Levels.fyi, or AmbitionBox to gauge expected ranges before your offer discussion.

In addition to base salary, many employers in this sector offer a comprehensive benefits package that may include:

  • Annual or performance-based bonuses
  • Health, dental, and vision insurance
  • Provident Fund (PF) and Gratuity contributions (India)
  • Paid Time Off (PTO), sick leave, and public holidays
  • Professional development budget and learning allowances
  • Stock options or Employee Stock Ownership Plans (ESOPs) at select companies
  • Flexible or remote working allowances
  • Parental leave and family health coverage

Note: The specific benefits offered by this employer should be confirmed during the offer stage. Not all benefits listed above may apply to every organisation or role type.

Work Arrangement

Type: Fully Remote

This role is designed for a fully remote work arrangement. You will have the flexibility to work from any location, provided you have a stable internet connection and can align with the team's core collaboration hours. The company supports remote employees with the necessary tools, virtual team-building activities, and regular check-ins to ensure productivity and a strong sense of belonging. Equipment and home-office stipends may be provided — check the job listing or confirm during the offer stage.

Typical Interview Process

While each organisation structures its hiring differently, candidates for this type of role typically go through the following stages:

  1. Resume and application screening
  2. Introductory phone or video call with HR
  3. Role-specific skill or competency interview
  4. Final interview with the hiring manager or panel
  5. Reference checks and offer discussion

Tip: Research the company's products, culture, and recent news thoroughly before each interview round.

About the Employer

Vercel is the organisation posting this opportunity. While full company details are available on the original job listing, here is what you should research before applying:

  • Company size and culture: Review the company's LinkedIn profile, Glassdoor reviews, and their official website to understand team size, work culture, and employee satisfaction.
  • Products and services: Familiarise yourself with what the company builds, sells, or delivers. Being knowledgeable about their offerings will set you apart during interviews.
  • Recent news: Search for any recent fundraising, acquisitions, product launches, or leadership changes — these often come up in interviews and signal company health.
  • Location and offices: The role is based in or around Remote. Confirm office address, remote policy details, and travel requirements during the process.
  • Where this listing was found: This job was sourced from WeWorkRemotely.

How to Apply & Preparation Tips

To apply for the Senior Product Security Engineer position, follow these steps:

  1. Tailor your resume: Customise your CV to match the specific requirements listed in the job description. Use keywords from the posting to pass Applicant Tracking System (ATS) filters.
  2. Write a compelling cover letter: Even if not mandatory, a concise cover letter demonstrating your enthusiasm and fit for the role significantly improves your chances.
  3. Apply via the original listing: Use the apply link on the original job post to submit your application. Avoid applying through third-party channels that may delay or lose your submission.
  4. Prepare for phone screening: Be ready for an initial call within 3–7 business days of applying. Have your resume and a quiet space ready.
  5. Follow up professionally: If you haven't heard back in 7–10 business days, a brief, polite follow-up email to the recruiter is acceptable and often appreciated.

Disclaimer: This listing is aggregated from a public job board for informational purposes. JobSetuu does not guarantee the accuracy or current availability of this position. Always verify the details on the employer's official careers page before applying.

check_circle

Discovery Success

smart_toy

JobSetuu AI

Online & Ready

delete_forever

Clear all messages?

This cannot be undone.

smart_toy

Powered by JobSetuu · Stored locally

Chat with JobSetuu AI